Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
- ID
- 30225
- Status
- summarized
- Published
- 30 Sep 2026, 1:30 PM
- Fetched
- 30 Sep 2026, 4:45 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/citrix-netscaler-cve-2026-88772-exploit.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 30 Sep 2026, 4:46 PM
- Tags
- Audience
- developers
What happened
watchTowr published exploit details for CVE-2026-88772 (CVSS 9.5), a pre-auth memory overflow in Citrix NetScaler ADC and Gateway's DTLS handshake handling inside the NetScaler Packet Processing Engine (NSPPE), which CISA says is under active exploitation in the wild. The bug is a parsing inconsistency: the handshake header's length field declares a 120-byte message while each fragment's fragment_length field says 1 byte, so reassembly stitches roughly 174 KB of NetScaler Buffer data into a scratch buffer of only 35,840 bytes because the vulnerable version never checks whether the next packet fits. Individual packets are 1,459 bytes, and the flaw can lead to remote code execution or denial-of-service.
Why it matters
If you or your employer don't run NetScaler ADC or Gateway, nothing in your stack changes this week — this is a patch-now item only for teams with that appliance in front of their services, since the path is pre-auth and exploitation is already observed. The transferable lesson is narrow and concrete: the overflow happens because the code trusted a declared per-fragment size (1 byte) while keeping the whole 1,459-byte record, so if you write any upload, websocket, or protocol reassembly handler, check whether you validate declared lengths against what you actually copy into a fixed buffer.
Discussion angle
Do the buffer arithmetic on screen: 120 records of 1,459-byte NSBs reassembled into a 35,840-byte scratch buffer, then ask who in the room has a parser or upload path that trusts a client-declared length field the same way.